[ Monday, October 10, 2016 ]


The Lesson of Care New England: Even if the breach isn't caused by it, the fact that you failed to manage your BAAs can cost you almost half a million dollars (OK, $400,000; I was telling some folks at a conference today it was $500,000, but I mis-remembered the amount, obviously).  That's the lesson: once OCR comes to investigate, whether as the result of a breach, a complaint, or an audit, anything that they find that you've done wrong is up for discussion, even if it has nothing to do with your particular breach.

Jeff [1:45 PM]

